Recently, many users from places like Shaanxi, Guangdong, and Gansu have reported that their Meituan accounts were hit with a wave of unauthorized charges from different locations—without them doing a thing or even knowing about it. The money was used to buy multiple group-buy vouchers, and the charges went through Meituan’s monthly pay feature. Some folks lost thousands of yuan.
On July 28, according to reports, based on evidence provided by affected users, Nupiao reached out to Meituan’s customer service. The response? The vouchers were already redeemed, so no refunds. If users want the backend details of those unauthorized orders, they’d need to go through a legal investigation process. Some victims have already filed police reports.
Meituan’s customer service explained that after an internal review, they believe these odd transactions might be the result of users’ phones being infected with malware. If someone accidentally clicks a malicious link, their device gets infected and remotely controlled, allowing hackers to bypass normal login checks and security alerts. The system then mimics real user behavior to place and redeem orders, making it nearly impossible for standard fraud detection to catch it.
A user named Mr. Guo from Henan lost about 4,000 yuan. He told Nupiao that his phone screen went black out of nowhere, so he shut it down and restarted. Another victim, Mr. Ling from Foshan, Guangdong, said his phone froze up and went black right after opening an app, forcing a reboot.
As of now, Meituan hasn’t issued any official statement about this mass hacking incident. When asked, their customer service team said they needed to check internally before getting back to us.
According to multiple victims, the fraud mostly happens late at night or in the early morning hours. The stolen money goes through Meituan’s monthly pay feature, and all the victims had enabled the small-amount no-password payment option for transactions under 500 yuan. The unauthorized orders were for things like food and leisure vouchers, which were quickly used up at stores in different cities. Many users didn’t realize something was wrong until they woke up to billing alerts the next day.

Complaints on platforms like Black Cat are also piling up fast. On July 29, Nupiao found a complaint from July 25 where a consumer said, On July 21, 2026, my Meituan monthly pay was hit for 2,473.53 yuan. The charges were all for meal vouchers, and I was in Gansu at the time. Meituan didn’t even send me a text alert.

Another consumer filed a complaint on July 20, saying, Around 5 AM on July 15, 2026, my Meituan monthly pay was drained of 3,522 yuan. I didn’t do anything—the system just let the scammers rack up eight charges in a row, costing me 3,522 bucks.

Nupiao checked Meituan’s official service agreement regarding small-amount no-password payments. It says that when users voluntarily enable this feature, they’re basically authorizing the platform to process those transactions. Users are supposed to keep their login info, passwords, phone verification codes, and personal details safe, never sharing them with anyone. If they suspect someone’s using their account without permission, they should contact Meituan’s customer service right away.

Many users who complained said they never leaked their passwords or lent out their devices—they followed all the security rules. But they did admit to clicking on weird links sent via text messages or social media recently.
Cybersecurity experts point out that this whole mess highlights a common weak spot in mobile payments. Unknown links are the main way malware and phishing scams spread. Once you click one, your device can get taken over remotely, exposing your account and payment info. And with small-amount no-password payments and monthly pay features turned on, it’s way easier for criminals to pull off multiple small transactions without setting off any alarm bells—causing big losses for users.
Internet users need to step up their mobile payment security game. Never click on unknown links in texts, group chats, or private messages. Don’t download apps from unofficial sources. When using daily apps and payment platforms, think about turning off the small-amount no-password payment feature if you don’t need it. Regularly check your bills and login device history, and kick out any unfamiliar devices. If you spot unusual charges or logins, freeze your account immediately, save screenshots and login logs, and then file a police report or reach out to the platform’s customer service.